{"podcast":{"title":"Research Saturday","slug":"research-saturday-1377435","podcast_index_feed_id":1377435,"rss_url":"https://feeds.megaphone.fm/cyberwire-research-saturday","website_url":"https://thecyberwire.com/podcasts/research-saturday","image_url":"https://megaphone.imgix.net/podcasts/720fb496-dcfb-11ea-a475-bbdae30535a9/image/8f3cd4038c81bba2a8ea4ca89f3e23c4.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks Inc.","episode_count":458,"summary":"Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.","last_synced_at":"2026-07-26T04:20:01.844149+00:00","page_url":"https://stenobird.com/podcast/research-saturday-1377435"},"episode":{"title":"Telegram for the throne.","slug":"telegram-for-the-throne","published_at":"2026-02-21T06:00:00+00:00","page_url":"https://stenobird.com/podcast/research-saturday-1377435/telegram-for-the-throne","show_page_url":"https://stenobird.com/podcast/research-saturday-1377435","url":"https://thecyberwire.com/podcasts/research-saturday/413/notes","audio_url":"https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW5632994674.mp3?updated=1771539670","summary":"Today we have Tomer Bar, VP of Security Research at SafeBreach Labs, discussing their work on \"Prince of Persia: A Decade of Iranian Nation-State APT Campaign Activity under the Microscope\". In this first installment of SafeBreach’s deep dive into the Iranian-linked APT known as “Prince of Persia,” originally exposed by Palo Alto Networks Unit 42, researchers reveal that the group never truly went dark after 2022—but instead evolved. Led by Tomer, the investigation uncovers new variants of Foudre and Tonnerre malware, expanded campaign scale, active C2 infrastructure through late 2025, and a shift toward Telegram-based command-and-control. The research provides rare, sustained visibility into nearly a decade of Iranian nation-state cyber operations, offering fresh indicators of compromise and insight into how the group continues to refine its tooling, obfuscation, and targeting. The research can be found here: Prince of Persia, Part 1: A Decade of Iranian Nation-State APT Campaign Activity under the Microscope","meta_description":"Today we have Tomer Bar, VP of Security Research at SafeBreach Labs, discussing their work on \"Prince of Persia: A Decade of Iranian Nation-State APT Camp…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1281,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/telegram-for-the-throne/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/research-saturday-1377435/telegram-for-the-throne.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}